The Challenge Cancelation Indicator tells the ACS and DS why an authentication stopped: 01 cardholder selected Cancel, 03 decoupled authentication timed out, 04 ACS timeout for other reasons, 05 ACS timeout because the first CReq never arrived, 06 transaction error, 07 unknown, 08 SDK timeout, 09 and 10 an Error Message exchanged over a CReq; 04 or 05 is mandatory when the status reason is 14. It is required in the CReq when the app-channel cardholder cancels, and in the RReq when the ACS identifies a cancellation, including abandonment during the browser challenge. For the app channel, when the ACS receives an Error Message from the SDK it sends the DS an RReq with status U and value 09, and when it rejects a CReq itself (Error Codes 101 or 302 for messages it cannot verify, decrypt or recognise, 203 and 201 for invalid or missing elements, 310 for a Split-SDK CReq not protected with A128GCM) it sends status U with value 10. With 09 or 10 the RReq carries Challenge Error Reporting, a copy of the Error Message sent or received.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.